Anyquery: AppleScript/JXA Code Injection via Unescaped URL in macOS Chrome Plugin (CVE-2026-47252) | HOL Guard CVE